peter bassill · operator
$ cve CVE-2023-0905 JSON

CVE-2023-0905 EXPLOIT

7.3
HIGH · CVSS 3.1 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221454 is the identifier assigned to this vulnerability.

Scoring

CVSS7.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS3.19% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2023-02-18
Last modified2026-06-17

Affected (1)

VendorProduct
employee task management system projectemployee task management system

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD